MCP definition
Model Context Protocol (MCP) is an open standard, introduced by Anthropic in 2024 and now governed by the Agentic AI Foundation under the Linux Foundation, that defines how AI applications connect to external tools and data sources. An MCP server exposes capabilities such as database queries, file access or API actions in a standard format, so any MCP-compatible AI client can discover and use them without custom integration code.
How does MCP work?
MCP uses a client-server design. A host application, such as a desktop AI assistant, an IDE or an agent framework, runs an MCP client for each server it connects to. Each MCP server wraps a system, such as a CRM, a file store or a code repository, and describes what it offers. Messages use JSON-RPC 2.0, carried over standard input and output for local servers or HTTP for remote ones.
When the host starts, it asks each server what it provides and passes those descriptions to the language model. When the model decides to use a capability, the client sends the request to the right server and returns the result to the model. The model never talks to the underlying system directly; the server controls exactly what is possible.
- Tools: actions the model can invoke, such as "create_ticket" or "run_query".
- Resources: data the application can read, such as files or records.
- Prompts: reusable templates a server offers for common tasks.
Why MCP matters
Before MCP, every AI application needed custom code for every tool, so connecting many apps to many systems multiplied integration work. MCP turns that into a single interface on each side: build a server once and it works with any compatible client, much as the Language Server Protocol let one language plugin work across many code editors. The protocol has since been adopted well beyond Anthropic by other AI providers, IDEs and agent frameworks, and in December 2025 Anthropic donated it to the Agentic AI Foundation, a vendor-neutral fund under the Linux Foundation co-founded with Block and OpenAI.
MCP vs function calling vs APIs
Function calling is a model capability: the model outputs a structured request to call a named tool. MCP is a protocol for packaging, discovering and connecting those tools across applications. An API is the underlying interface of the system itself. In practice they stack together: an MCP server wraps a company API, the host lists its tools to the model, and the model uses function calling to request one.
Example: an internal MCP server
A company builds one MCP server over its CRM and ticketing system, exposing tools to look up a customer, list open tickets and draft a ticket update. Staff connect it to the AI assistant and code editor they already use. A support engineer asks, "What open issues does this customer have, and what changed in their last deployment?" and the assistant answers using live data, with every call logged by the server.
MCP security considerations
An MCP server gives a model real capabilities, so it needs the same care as any integration with production systems. Nexzem builds MCP servers for client systems with scoped permissions, OAuth authentication and audit logging from the start, before any client data is exposed.
- Install only trusted servers, since descriptions and outputs can carry prompt injection.
- Give each server the narrowest permissions it needs, ideally per user.
- Authenticate remote servers, typically with OAuth.
- Require human confirmation for actions that change or delete data.
- Log every tool call for audit and debugging.